This is not that easy. MCS Separation requires coordination between
the process and the data. You need an MCS manager to set the labels
on the data and on the process. For example libvirt uses MCS Separation. Before launching a process it labels all of the image content with a unique MCS label, then launches the VM (qemu) process with a matching MCS Label. In order to get what separation in your case you would have to have a controller launching the different services with MCS labels. On 08/25/2014 08:40 AM, David Compton
wrote:
|
-- selinux mailing list selinux@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/selinux